New Critical Security Update For SP Page Builder Pro - Question | JoomShaper

New Critical Security Update For SP Page Builder Pro

J

jcalvert

SP Page Builder 19 hours ago

I just found out that there is another critical security update for SP Page Builder Pro, which is 6.7.1.

It's difficult to find the changelog for the software, which is here:

https://www.joomshaper.com/downloads/extension/sp-page-builder-pro-next

The changelog doesn't indicate that it's a critical security update.

And, I never got an email to warn me of this necessary update.

It seems other people are getting these emails, but I am not. Please sign me up. Please also indicate if I need to whitelist the sender. What is the sending email address?

thank you, JC

0
13 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 18 hours ago #231423

Hi,

  1. All users have gotten the newsletter, it was sent in 6.7.1 premiere day (27 July 2026), 2 weeks ago.
  2. Not really. Easy to remember, it's before Download button : https://www.joomshaper.com/downloads/extension
  3. It wasn't (it was hardening), previus version was.
  4. Check SPAM folder. It all depends on you mail-box settings. Add our e-mail to your safelist.
  5. You need system that will update your extensions without checking manually, there are solutions for Joomla's already, as component or online service.

And before you will write "I wasn't informed etc" in next days or week ..... the upcoming update

SP Page Builder v6.8.0 Changelog

  • Update: Added a Joomla 3 version guard to the installer script. (to stops J!3 users from trying)
  • Update: Hardened input validation, file handling, and access checks across the component.
  • MORE

You're welcome.

0
J
jcalvert
Accepted Answer
16 hours ago #231444

Hi Paul,

Sorry, I was relying on the AI, and the AI said... critical security update... SQL injections. It mentioned a CVE. You are saying it wasn't a critical update... OK, that's a relief. Would you call it a non-critical security update? Is v6.8.0 what you consider a security update?

I am just looking for a solid way to know when you guys have a security update for Page Builder or Helix. The June wave was traumatizing for me. No, I don't want to pay for mysites.guru. I'll look into the automatic features built into Joomla.

I'm fine if you want to change the title on the post, if you can.

I have whitelisted joomshaper.com incoming email.

Please confirm that my email address (see below) is on your email list for updates like this, and that the notifications come from @joomshaper.com.

Thanks for making these updates.

JC

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 16 hours ago #231445

Sorry, I was relying on the AI, and the AI said... critical security update.

About facts from last days, but AI is Now Faking even Critical CVEs :  https://www.youtube.com/shorts/uHK-HBTJMfM


I suggest to use every update. Also becuase it fixes small issues and add new features. The same as you do for your browser.


There is also free component that have auto-update for Joomla. (info & link below)


I guess, it's not possible to change forum post title( :/ ), only content inside or delete whole topic, if you got all the answers.


I checked, and your correct e-mail is already in our system. Thanks.

0
D
djumla
Accepted Answer
14 hours ago #231459

Hi,

David here, teamlead of the Joomla Security Team.

I'm following up with you for a couple of weeks now regarding the unpatched SQL injection, getting any sort of meaningful feedback from you guys has been "difficult" - and now you end up publicly posting about activly expoited security issues without a patch being available?

With all due respect: could you please bring your team up to speed in terms of basic security industry standards (how to handle a security issue, what does "responsible disclosure" mean, communication best practices with end users and reporters), provide feedback regarding the open issues asap and most importantly ship that damn release for an actively exploited issue.

1
PH
Pascal - HTProtect.org
Accepted Answer
13 hours ago #231466

HTProtect 2.6.7 includes a fix for that (Changelog).

The rollout as a self-update has just started and will be completed within the next 3 hours.

0
abrac Büro & Grafikservice Andrea Brandt
abrac Büro & Grafikservice Andrea Brandt
Accepted Answer
13 hours ago #231467

Hi, Klaus from Germany here, long time Coústomer. After all that shit in the last month' i bought mysitesguru for all my sites...

And he wrote on every site this (today, August 10, 2026): ////-> in hidden content, just Paul aked, O.K.///

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 13 hours ago #231469

Our update is planned for this week (tomorrow probably). But it will include more than only that change.

@Pascal, we both agree that using firewall is MUST HAVE, no matter what extensions you use.

@David, I agree, I removed info from my post, but @Klaus have to do the same! !!! bitte !!! Cut & paste your content in "Hidden Content" area (!) For security reasons !!

0
D
djumla
Accepted Answer
12 hours ago #231470

@David, I agree, I removed info from my post, but Klaus have to do the same! !!! bitte !!!

Well, that underlines my point I guess: As mentioned a couple of times now, the SQLi vector is not reported through responsible discloure procedures but is actively exploited in currently running campaigns. The information about the issue is therefore already public. The real key problem is that there is no patch.

Other reported potential issues are still under responsible disclosure, but due to lack of feedback from your end I have no idea if those issues are indeed valid and when they will be adressed.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 12 hours ago #231471

For those questions use e-mail, not public forum.

0
abrac Büro & Grafikservice Andrea Brandt
abrac Büro & Grafikservice Andrea Brandt
Accepted Answer
12 hours ago #231472

O.K., Paul, I did. Sorry, but I feel a bit ...insecure.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 12 hours ago #231473

Danke. As we all know, danger times in EU, cyber crimes on the net, mailbox full of spam, AI takes our jobs, "engineers and doctors" on the streets, extreme heatwaves and RU drones in the air. I feel the same.

0
D
djumla
Accepted Answer
12 hours ago #231474

For those questions use e-mail

Well, I am using e-mail for weeks, but getting proper answers is... challening.

So, I would suggest you do these three things:

  • publish the patch for the SQLi - and not tomorrow or until the end of the week, but today
  • get an overview of the other pending reports by myself and the reporters that have cc'ed me
  • act according to esablished best practices - and in order to make your life a little easier, I've prepared a guide: https://manual.joomla.org/docs/next/building-extensions/security/

Ping me if you have any further questions

1
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 12 hours ago #231475

Thanks. Shared with our developers, but they are in different time zone.

0